Datadog provides cloud-scale monitoring and security for metrics, traces and logs in one unified platform.
Senior Software Engineer – Security Libraries
Location
France
Posted
4 days ago
Salary
0
Seniority
Senior
Job Description
Senior Software Engineer – Security Libraries
Datadog
• Design, build, and own security integrations and detections (WAF, RASP/exploit prevention, API Security, IAST, SCA) across multiple libraries, with .NET and/or Java as your primary focus. • Take projects from prototype to deployed, correct, operable, and maintainable, writing code that safely instruments thousands of applications in production. • Own your systems operationally: monitor production telemetry (e.g., WAF/RASP timeouts, performance and cost), debug challenging cross-system issues, and drive down customer-facing problems. • Shape the roadmap: help define the OKRs for the systems you own, break features into components other engineers can build in parallel, and drive designs and RFCs to alignment across our security library teams. • Partner with product management, backend, and frontend teams to turn product ideas, new detections, agentic onboarding, API security, into capabilities customers actually adopt. • Mentor teammates and act as a force multiplier: raise the bar on code quality and testing, and make the whole team more effective than you'd be on your own. • Represent Datadog in the relevant language and security communities.
Job Requirements
- You are an expert in at least one of .NET (C#) or Java, and you're a polyglot who can contribute idiomatically across other libraries when needed with the support of their main maintainers. For each language you use, you write clean, correct, well-tested, performant, idiomatic code.
- You have strong software-engineering fundamentals: you consistently ship modular, maintainable code with little guidance, and you leave code in substantially better shape than you found it.
- You have a product-engineering mindset: you care about user experience and product outcomes as much as the code, weigh technical trade-offs against customer impact, and help decide what to build, not just how.
- You have experience building and shipping libraries or SDKs consumed by other developers, and you understand packaging, versioning, and backward compatibility.
- You care about performance and cost, in both time and space, and you have experience measuring and optimizing to that end.
- You are operationally mature: you take full accountability for what you ship in production, even when others work on it.
- You communicate clearly in writing and in person, you drive alignment through RFCs and informal collaboration, give bad news early, and give constructive, empathetic feedback to peers.
- You have a BS/MS/PhD in a STEM field or equivalent experience.
Benefits
- Health insurance
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Researcher
Freedom of the Press FoundationProtecting journalists, whistleblowers, and the public’s right to know.
• Conduct application security reviews across SecureDrop components. • Assist in performing threat modeling for new features and architectural changes. • Review pull requests and design documents with a focus on the security properties of new features and the security implications of architectural changes. • Assist in preparing materials for and reviewing findings from third-party security audits. • Advise on hardening strategies for SecureDrop’s deployment environments. • Review and integrate security automation tooling, such as LLMs, static code analyzers, and other tools that can mitigate or discover security vulnerabilities.
• Function as the OT and Cybersecurity team representative in engineering and technical design updates and discussions • Authorize and oversee DEPCOM Cybersecurity policies across active EPC projects including Remote Access Procedures and Project Handoff deliverables • Review EPC requirements and specifications for the Cybersecurity, Networking, and NERC Compliance portions of the EPC contract • Coordinate technical reviews with SCADA suppliers, customers, and the Project Integration team ensuring that the design meets the EPC contract and Industry standards • Witness the SCADA Factory Acceptance Testing and follow through identified punch list items • Identify technical and compliance risks and communicate to the SCADA PM any impacts to the project schedule and cost • Provide subject matter expertise on the SCADA network architecture for the substation, PV, BESS and associate connected network peripherals • Collaborate with SCADA Vendors and Commissioning to troubleshoot network equipment that is not performing as designed • Travel to the job site as required to provide support • Advise owners and subcontractors on proper IT/OT Network segmentation • Support SCADA team with owner related questions on CIP documentation and vulnerability scans
• Design, deploy, maintain, and operate network security infrastructure components. • Provide Level 2 / Level 3 support for security platforms, including firewalls and related technologies. • Perform operational tasks, including configuration changes, incident resolution, and infrastructure updates. • Support cybersecurity projects and participate in technical deliveries related to network security initiatives. • Collaborate with internal stakeholders and service partners to resolve infrastructure and security-related issues. • Maintain and update technical documentation, runbooks, and operational procedures. • Participate in an on-call support rotation (approximately one weekend in six) to provide production support coverage.
Role Description The Application Security Analyst is responsible for ensuring the security of homegrown and 3rd party applications. The role emphasizes analytical and advisory responsibilities rather than hands-on implementation, supporting secure architecture practices, overseeing the security posture of applications (including cloud and AI solutions), and providing transparency to IT management through status reporting and risk insights. - Assess and advise on security architecture and configuration of systems, applications, and infrastructure. - Collaborate with the DevSecOps team on state-of-the-art procedures. - Independently assess the results of security test reports like static code analysis, dynamic application analysis, and penetration testing. - Support development teams with the mitigation of findings. - Work within a fast-paced, agile environment collaborating with business and technology teams across the Americas region to implement and support next generation security solutions. Qualifications - Knowledge of OWASP Top 10 and ASVS frameworks including best practice implementations. - Experience with cloud security and AI security standards (e.g. ISO 27017, CSA CCM, NIST AI RMF, ISO 42001) and best practices. - Ability to interpret different coding languages including Python, Java, ReAct, and JavaScript as well as further widespread languages. - Excellent organizational and analytical skills. - Ability to analyze data, draw conclusions, interpret results, and make recommendations with respect to various IT systems. - Ability to communicate effectively with all levels of management. - Ability to work effectively in a global environment, including awareness of and sensitivity to cultural differences. - Ability to produce high quality work under pressure or tight deadlines. - Good written, oral, and interpersonal communication skills. - Strong Microsoft Office skills (Word, Excel, PowerPoint). - Strong attention to detail. - Ability to multi-task. Requirements - Bachelor’s degree in information technology, or related field of study preferred. - 3+ years of experience required in application security, DevSecOps, or security architecture. - Experience with best practices and tools in API security, container security, modern identity frameworks, and supply chain security. - Knowledge of most common SAST, DAST, and penetration testing tools and procedures. - Experience with CVSS, risk management, and GRC tools. - Experience and knowledge of Microsoft Office (Word, Excel, PowerPoint). - Process automation experience preferred. - Experience working with a global organization and/or interacting with colleagues in foreign jurisdictions. - Security certifications such as CISSP, CISA, CEH, OSCP, or CCSP are preferred. Benefits - Competitive Pay - Bonus Programs - Retirement Savings - 401k with company match - Medical, Dental, Vision, Well-being programs - FSA/HSA availability - Tuition Reimbursement - Paid Time Off including vacation and sick time - Company Paid Holidays and Floating Holidays - Paid Parental Leave - Employee Discount Program - Employee Assistance & Work Life Program - Short Term and Long-Term Disability - Life Insurance



